> Markdown version of [/jobs/ext/591025-iam-engineer-hybrid-onsite](https://www.wearedevelopers.com/jobs/ext/591025-iam-engineer-hybrid-onsite). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAM Engineer - Hybrid Onsite - **Company:** Insight Global - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $104,000.0 - $110,240.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Active Directory, User Authentication, Authentication Protocols, Automation of Tests, Microsoft Azure, Bash Shell, C++ (Programming Language), Cyber Security, Data Centers, Multi-Factor Authentication, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), Microsoft Operating Systems, OAuth, OpenID, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Ruby, Zero Trust Network Access, Security Assertion Markup Language (SAML) - **Published:** June 12, 2026 - **Apply:** https://dejobs.org/x/x/D82474B2F79B405F883003F04CEA1297/job/ ## About the Role * 7+ years in IAM * Expert understanding of IAM concepts including authentication, authorization, RBAC, and least privilege * Hands-on experience with Entra ID and Active Directory * experience with troubleshooting IAM issues around certificates, create accounts, etc * familiarity with identity management (users, groups, accounts, etc), Authentication (SSO, MFA), Authorization & Access control, etc * Familiarity with certificate lifecycle management systems / PKI * understanding of authentication protocols including Kerberos, SAML, OAuth, OIDC, etc. * Understanding of zero-trust and modern security architectures - Automation of security tasks (Python, C++, Java, Ruby, Bash etc) * lawfirm background * Security certifications (Security+, CEH, CRISC, CISM, CISA, CISSP, CCNP Security, GIAC GSEC, and Microsoft Systems Developer training) ## Description An international law firm is looking for an IAM Engineer to join their Security team and will support the design, implementation and ongoing operations of core enterprise identity and access management and PKI certificate systems. The Firm has more than 1,300 lawyers and has offices that span the globe from Boston, New York, Beijing, Brussels, Hong Kong, Houston, London, Los Angeles, Palo Alto, Sao Paulo, Tokyo and Washington, D.C. The Firm consistently ranks among the world's leading law firms. The Firm has the following practice areas: Corporate, Litigation, Banking & Credit, Capital Markets, Mergers & Acquisitions, Real Estate, Restructuring and Private Funds. They support clients in a variety of industries such as Energy (Oil & Gas, Power & Renewables), Financial Services, Healthcare & Life Sciences, Infrastructure, Technology, Insurance & Reinsurance, and Data Centers. This role will be 3 days onsite in NYC and the remaining 2 days remote, with the exception of the first two weeks of training which will be 4 days onsite. This role will join a team of two resources responsible for IAM operational tasks in Entra/Active Directory and special projects. They will be responsible for responding to IAM tickets that come through, troubleshooting issues and ensuring the appropriate approval processes are in place, certificates, adding accounts, granting access, etc. They are mostly onprem AD but there will be some in Azure EntraID., * Administer and support Active Directory and Microsoft Entra ID environments, including users, groups, organizational units, and access policies. * Support identity lifecycle processes including provisioning, modification, and account termination. * Manage and support authentication protocols and systems including Kerberos, LDAP, SAML, and MFA platforms * Onboard applications to SSO platforms * Administer enterprise PKI (public key infrastructure), including certificate issuance, renewal, revocation, and support * Assist in the design, maintenance, and testing of role-based access and entitlements across infrastructure and applications. * Assist with periodic access reviews and certification campaigns. * Implement access requests according to established procedures and security policies, ensuring least privileged access. * Provide Tier 1 & 2 support for IAM related issues, troubleshooting access problems and escalating complex issues to leadership. * Create and maintain clear and concise documentation related to IAM processes, configurations, and troubleshooting steps. * Assist with monitoring IAM systems for anomalies and generate reports on access activity. * Participate in testing of IAM system updates, patches, and new features. * Assist in the development and implementation of automation scripts to streamline IAM processes (e.g., PowerShell, Python). * Work closely with other IT teams (Help Desk, Applications, Infrastructure, Information Security) to ensure seamless integration of IAM solutions. They may also be asked to help with special projects like upgrading their MFA system on all server/laptops; implementing new vendor for Identity Validation and go through vendor selection, POC, Implementation etc; deploying browser plug in for secret server; assist in IGA solution implementation etc. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)